Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9578

Опубликовано: 06 фев. 2017
Источник: redhat
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.

A vulnerability was discovered in SPICE in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Virtualization 4distributionAffected
Red Hat Enterprise Linux 6spice-serverFixedRHSA-2017:025306.02.2017
Red Hat Enterprise Linux 7spiceFixedRHSA-2017:025406.02.2017
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7imgbasedFixedRHSA-2017:054916.03.2017
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7redhat-release-virtualization-hostFixedRHSA-2017:054916.03.2017
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7redhat-virtualization-hostFixedRHSA-2017:054916.03.2017
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7rhevm-applianceFixedRHSA-2017:055216.03.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=1399566spice: Remote DoS via crafted message

EPSS

Процентиль: 87%
0.03335
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.

CVSS3: 7.5
nvd
больше 7 лет назад

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.

CVSS3: 7.5
debian
больше 7 лет назад

A vulnerability was discovered in SPICE before 0.13.90 in the server's ...

CVSS3: 7.5
github
больше 3 лет назад

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.

suse-cvrf
почти 9 лет назад

Security update for spice

EPSS

Процентиль: 87%
0.03335
Низкий

7.5 High

CVSS3

5 Medium

CVSS2